CVE-2024-3892

HIGH

Telerik UI for WinForms 2021.1.122-2024.2.514 - Local Code Execution via Untrusted Theme Assembly

Title source: llm
STIX 2.1

Description

A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system.

References (1)

Core 1

Scores

CVSS v3 7.2
EPSS 0.0003
EPSS Percentile 9.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
progress/telerik_ui_for_winforms 2021.1.122 - 2024.2.514
Published May 15, 2024
Tracked Since Feb 18, 2026